This translation is provided for information only. The Spanish version is the legally binding one and prevails in the event of any discrepancy.

Privacy Policy

Last updated: August 2026

In compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and Spanish Organic Law 3/2018 of 5 December on the Protection of Personal Data and guarantee of digital rights (LOPDGDD), we inform you about the processing of your personal data.

1. Data controller

Company name: Volodymyr Tarasov
Tax ID (CIF): Z4055528N
Registered office: Pont de la Cros 16 4º 3a, 08918, Badalona, Barcelona
Email: hola@trimly.es

2. Data we collect

We collect the following categories of personal data:

  • Identification data: first name and surname, phone number.
  • Service usage data: booking history, service preferences, communications with the business.
  • Technical data: IP address, browser type, session data (essential cookies).
  • Account data (business owners): email address, billing details, subscription information.

3. Purpose and legal basis for processing

We process your data for the following purposes:

  • Managing end-client bookings: performing the service contract between the client and the business (Art. 6(1)(b) GDPR).
  • Sending booking notifications: confirmations, reminders and cancellation notices via WhatsApp (Art. 6(1)(b) GDPR — performance of the contract; Art. 6(1)(a) for additional marketing communications).
  • Managing the business owner’s account: registration, subscription, billing and support (Art. 6(1)(b) GDPR).
  • Compliance with legal obligations: retention of accounting and tax records (Art. 6(1)(c) GDPR).
  • Service improvement and statistical analysis: aggregated, anonymous usage statistics (legitimate interest, Art. 6(1)(f) GDPR).

4. Retention periods

We keep your data for as long as necessary for the purpose for which it was collected, observing the applicable legal periods:

  • Booking and client data: 3 years from the last booking, unless a longer legal retention obligation applies.
  • Billing and contract data: 5 years (art. 1964 of the Spanish Civil Code) or up to 10 years where tax obligations exist.
  • Account data (business owners): for the duration of the contract and up to 5 years after its termination.
  • Session data and technical cookies: as per the duration set out in our Cookie Policy.

5. Recipients and sub-processors

Your data may be disclosed to the following recipients and sub-processors:

  • Telnyx LLC: sending notifications via the WhatsApp Business API (processor, USA — EU standard contractual clauses).
  • Stripe Inc.: processing subscription payments for business owners (processor, USA — EU standard contractual clauses).
  • Cloudflare Inc.: file storage (profile images, logos) on Cloudflare R2 (USA — EU standard contractual clauses).
  • Upstash / Redis: technical cache (no identifying personal data among sensitive data).
  • Vercel Inc.: website hosting and cookieless anonymous web analytics (aggregated traffic statistics with no personally identifiable information; USA — EU standard contractual clauses).
  • Crisp IM SARL: support chat on our website and in the admin panel, loaded only when you open it (France; servers in the Netherlands and Germany — European Union).
  • Microsoft Ireland Operations Ltd. (Clarity): website usage analysis via session recording and heatmaps, only if you give your consent in the cookie notice (Ireland, with possible transfers to the USA — EU standard contractual clauses).
  • Meta Platforms Ireland Ltd.: advertising measurement (Meta pixel) on our website, only if you give your consent (Ireland, with possible transfers to the USA — EU standard contractual clauses).
  • TikTok Technology Limited (Ireland) and TikTok Information Technologies UK Limited (United Kingdom): measurement and optimisation of our advertising campaigns through the TikTok pixel and its Events API, only if you give your consent. Unlike the other recipients in this list, TikTok does not act as a processor but as a joint controller together with us (Art. 26 GDPR). That joint controllership is limited to the collection and transmission of the event data and to the measurement reports we receive; for profiling and ad optimisation on its platform, TikTok acts as an independent controller under its own policy. Under our agreement with TikTok, it is TikTok that handles requests for access, rectification, erasure, restriction and portability (Arts. 15 to 20 GDPR) in respect of the data it holds; you may equally contact us and we will pass your request on. You can find the details in TikTok’s privacy policy and in section 6 of this policy on international transfers.
  • Google Ireland Limited: web analytics (Google Analytics), advertising measurement (Google Ads) and tag management (Google Tag Manager) on our website, only if you give your consent in the cookie notice (Ireland, with possible onward transfers to the USA — EU standard contractual clauses). Not used on the barbershops’ booking pages.
  • Public authorities: where required by law.

We do not sell or transfer your personal data to third parties for those third parties’ own commercial purposes.

6. International transfers

Some of the sub-processors listed in the previous section (Stripe, Cloudflare, Vercel) are established in the United States. Transfers are made under the Standard Contractual Clauses approved by the European Commission (Implementing Decision 2021/914), which provide appropriate data protection safeguards.

Google Ireland Limited is established in the European Union, although data collected with your consent through Google Analytics and Google Ads may be transferred onward to Google LLC in the United States under those same Standard Contractual Clauses.

TikTok calls for a specific warning, and we want to give it to you plainly. If you accept the advertising cookies, the data collected by the TikTok pixel and by its Events API is disclosed to TikTok. TikTok states that it stores European Economic Area users’ data in European data centres located in Norway and Ireland (the so-called ‘Project Clover’), but staff located outside the EEA, including in China, have had remote access to that data. On 30 April 2025 the Irish Data Protection Commission imposed a fine of 530 million euros on TikTok for breaching Art. 46(1) GDPR, because it had not demonstrated that the transferred data enjoyed protection essentially equivalent to that guaranteed within the European Union, and for a lack of transparency (Art. 13 GDPR). The Irish High Court upheld that finding in June 2026; both the fine and the order suspending the transfers are stayed on an interim basis pending the determination of the appeal, but the declaration of unlawfulness still stands. Unlike the other recipients mentioned in this policy, this disclosure of data is not covered by Standard Contractual Clauses or by any other appropriate safeguard under Chapter V of the GDPR, and we cannot assert that a level of protection equivalent to the European one exists. In line with the position of the Spanish Data Protection Agency, we expressly warn you that you are accepting this transfer assuming the risk arising from the absence of an adequacy decision and of appropriate safeguards. If you prefer to avoid it, you need only reject the advertising cookies in the cookie notice or withdraw your consent at any time: in that case the TikTok pixel is not loaded and no data is sent to TikTok.

You can request information about these safeguards by writing to hola@trimly.es.

7. Your rights

Under the GDPR and the LOPDGDD, you have the right to:

  • Access: obtain confirmation as to whether we process your data, and a copy of it.
  • Rectification: request the correction of inaccurate or incomplete data.
  • Erasure: request deletion of your data where, among other cases, it is no longer necessary for the purposes for which it was collected.
  • Objection: object to processing based on legitimate interest.
  • Restriction of processing: request that we suspend processing in certain circumstances.
  • Portability: receive your data in a structured, commonly used, machine-readable format.
  • Withdrawal of consent: where processing is based on consent, you may withdraw it at any time without retroactive effect.

To exercise your rights, please contact hola@trimly.es.

If you believe the processing infringes the regulations, you may lodge a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es.

8. Minors

Our services are aimed at people over 16 years of age. We do not knowingly collect personal data from minors below that age without the consent of their parents or legal guardians. If we detect that we have collected a minor’s data without the relevant consent, we will delete it immediately.

9. Cookie policy

We use essential cookies for the platform to work and, only with your consent, analytics and session-recording cookies (Google Analytics and Microsoft Clarity) and advertising measurement cookies (Google Ads and the Meta pixel) on our website. All of them load through Google Tag Manager, are disabled by default and are only activated if you accept them. For more information, see our Cookie Policy.

10. Changes to this policy

We may update this Privacy Policy to reflect regulatory changes or changes to our services. We will notify you of relevant changes through a notice on the platform or by email. The updated version will always be available on this page with the date it was last updated.

11. Contact

For any query relating to the processing of your personal data, you can contact us at:

  • Email: hola@trimly.es
  • Postal address: Pont de la Cros 16 4º 3a, 08918, Badalona, Barcelona

12. Is providing your data mandatory?

To make a booking through the platform, providing your name and phone number is mandatory. This data is necessary to perform the hairdressing or barbering service contract and to send you the notifications linked to your booking.

Without this data the booking cannot be completed. All other data (service preferences, for example) is optional and not providing it does not prevent basic use of the service.

13. No automated decision-making

Volodymyr Tarasov does not carry out any automated decision-making producing legal effects concerning data subjects or similarly significantly affecting them. Nor do we carry out profiling based on the personal data processed through the platform.

14. Note on consent as a legal basis

Most of the processing we carry out is based on Art. 6(1)(b) GDPR (performance of a contract to which the data subject is party), not on consent. This means that:

  • Processing your data to manage your booking and send you the associated notifications does not require your explicit consent: it is necessary to provide the service you have requested.
  • We only ask for your consent (Art. 6(1)(a) GDPR) for additional purposes, such as sending commercial or marketing communications that go beyond the ordinary handling of your booking.
  • You may withdraw your consent at any time for the purposes based on it, without affecting the lawfulness of processing carried out before that withdrawal or processing based on other legal grounds.